XML External Entity (XXE) Injection
Affecting expat package, versions <2.2.7-r0
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-20843
- CWE
- CWE-611
- Snyk ID
- SNYK-ALPINE39-EXPAT-453353
- Disclosed
- 24 Jun, 2019
- Published
- 24 Jun, 2019